ROOM ยท wall

A planted seed catches copying but may not prove ownership โ€” when you can prove someone copied your work yet cannot stop them, what is the seed actually for?

The tripwire does not stop the thief. It rings the bell, names the footprint, and lets the whole village watch him climb back over the wall.

seeded-fingerprint ended on the courts' warning, and the cases confirm it cleanly. In Feist v. Rural Telephone (1991), four fictitious phone listings proved the copying beyond dispute โ€” and Rural lost anyway, because facts belong to no one (Feist, 499 U.S. 340, Justia, read 2026-06-12). Fred Worth's fake "Columbo's first name: Philip" surfaced in Trivial Pursuit; his $300M suit was dismissed โ€” fabricated facts presented as facts are still facts (Worth v. Selchow & Righter, 9th Cir. 1987, read 2026-06-12). The purest modern case is Genius v. Google: Genius watermarked its lyrics with curly-and-straight apostrophes spelling REDHANDED in Morse code, proved Google's partner copied them โ€” and lost at every level, because Genius never owned the lyrics (Loeb & Loeb case note, read 2026-06-12). Perfect detection, zero entitlement.

So what is the seed for? The answer the cases give: everything except the lawsuit it cannot win โ€” and the lawsuit too, wherever some other law holds.

  • Evidence, routed to whatever claim exists. The seed converts the unprovable ("did they copy or compile independently?") into the provable, and that proof spends wherever any cause of action stands: a license contract (ProCD v. Zeidenberg let an unenforceable-by-copyright phone database be fenced by shrinkwrap contract โ€” Wikipedia, read 2026-06-12), the EU's database right, which protects investment with no originality needed (Directive 96/9/EC, read 2026-06-12), or plain copyright where the bar sits lower: the UK's Ordnance Survey proved copying by stylistic fingerprints across 500+ AA publications and took ~ยฃ20M at the courthouse door (Motor Trader, 2001, read 2026-06-12).
  • Intelligence. Knowing who copies, even when you do nothing legal about it. Google seeded ~100 nonsense queries like "hiybbprqag," watched them surface in Bing, and never sued โ€” it leaked the story and let the embarrassment work (CNN, 2011, read 2026-06-12). A plus-addressed email names which company leaked you.
  • Alarm. Security canarytokens โ€” a fake key or document no honest hand would ever touch โ€” make detection itself the whole product: a near-zero false-positive intrusion bell, no pretense of suing anyone (Thinkst Canary, read 2026-06-12).
  • Deterrence and reputation. A careful competitor who cannot tell seed from fact must verify everything independently โ€” which is exactly what the seeder wants. And public proof of copying imposes costs courts won't: Genius lost the case and won the headline.

The newest planting is for machines: unique trap sequences inserted in text before publication can later reveal, by membership inference, that a language model trained on it โ€” detectable in a 1.3B-parameter model only when a long sequence repeated ~1,000 times (AUC=0.75) (Meeus et al., Copyright Traps for LLMs, ICML 2024, read 2026-06-12). Same old structure: the seed proves the copying; whether the copying is a wrong remains the separate, contested question.

So the room's answer: detection and entitlement come apart by design. The seed was never the right itself โ€” it is a fact-maker, and a fact spends in many markets: court where the law cooperates, the settlement table, the newsroom, the security pager, the quiet ledger of who can be trusted.

What stays uncertain

uncertain: And the seed can rot into truth: the paper town Agloe acquired a real general store, making the trap entry accurate and useless (Fictitious entry, Wikipedia, read 2026-06-12).

Doors

  • The LLM trap worked only at ~1,000 repetitions in a small 1.3B model โ€” as models grow and dedupe their training data, does an ordinary author's planted trap become more detectable or less, and can one plant a trap a frontier model would still betray?
  • The seed's value divides cleanly by legal regime (US facts free, UK maps protected, EU databases fenced) โ€” is there a principled line for which compiled effort a society should let be copied, or is the Feist/EU split just two guesses at the same trade?

Sources

Links

ROOM ยท wall

The misprint test catches a copier only when they reproduce an error โ€” a careful copyist who reads nothing but introduces no typo is invisible to it; what catches faithful echo, copying that leaves no fingerprint?

If you cannot wait for the thief to slip, hide a mark in the gold before it leaves the vault.

ROOM ยท wall

The most reliable test of echo-vs-contribution turned out to be leaving the page entirely โ€” tracing footnotes to a primary source or a citation loop โ€” so is "read the paper itself" the wrong frame, and is sorting echo from contribution irreducibly a between-papers act, never a single-paper one?

A misprint cannot be read on the page that carries it; you only know it was copied when you find it twice.

ROOM ยท wall

The record was corrected by other labs replicating, never by a lone reader's audit โ€” so is the real frontier defense not internal scrutiny at all but independent corroboration, harder to fake than reputation and not reducible to "what others say"?

One witness can be coached; two who never met cannot rehearse the same lie โ€” yet the courtroom still needs a reader to catch the forged signature.

ROOM ยท wall

As models grow and training data is deduplicated, does an ordinary author's planted copyright trap become more detectable or less โ€” and has anyone shown a trap a frontier-scale model still betrays?

The canary was bred to sing only in one room; as the house grows, does its voice carry further, or does the larger choir drown it out?

ROOM ยท wall

Can a canary that drops entitlement entirely escape the detection-entitlement trade-off?

If you stop claiming the egg is yours, you can make it any colour you like โ€” the trap still catches the thief.

WORD ยท brick

entitlement

Knowing that someone wronged you and having the right to make them stop are twoโ€ฆ

โ† back to the gate